About this platform
About IACS Radar
IACS Radar — Industrial Cyber Exposure & Intelligence — is a defensive intelligence platform for OT, ICS and IACS, with a focus on the energy sector, electricity grids and substations.

From abstract security requirement to workable OT practice
IACS Radar arose from the conviction that good OT cybersecurity starts with insight. Insight into the systems connected to a network, into current vulnerabilities and threats, but also into the standards and measures that help organisations demonstrably better secure industrial environments.
My name is Marco Vader. I work at the intersection of cybersecurity, industrial automation and critical energy infrastructure. In my daily work at Qirion I deal with the security of operational technology within substations and other environments where availability, reliability and safety are essential.
My background lies in both IT infrastructure and cybersecurity. That is why I look not only at policy and compliance, but also at technical and organisational practice. What does a security requirement mean for an engineer? Which measure is feasible in an existing installation? How do you demonstrate that a system has been set up securely, without losing sight of the continuity of the industrial process?
In doing so, I work with topics such as:
- •IEC 62443 and OT security management
- •Zones, conduits and network segmentation
- •Security by design for substations
- •Hardening of industrial computers and engineering workstations
- •Vulnerabilities, CVEs and CISA KEV information
- •Patch and vulnerability management
- •Security of IEDs, RTUs, HMIs and industrial networks
- •ISO 27001, NIS2 and demonstrable risk control
The common thread in my work is translating abstract standards, risks and threat intelligence into measures that are technically sound, explainable and practically feasible.
What makes IACS Radar different — why did we start developing this?
NVD, CISA and tools such as OpenCVE each provide separate, raw data. IACS Radar combines the most recent CISA ICS-CERT advisories with the KEV catalogue (confirmed active exploitation) and enriches this with NVD and EPSS data into one coherent IACS Radar priority score per vulnerability, specifically aimed at OT/ICS in the energy sector. Not yet another CVE list, but interpreted context. See the methodology for the full approach.
- •My Radar — follow vendors, products or CVEs and see at your next visit immediately what has changed.
- •Vendor and product pages — navigate by product names (e.g. SIPROTEC 5) instead of individual CVE IDs.
- •Asset Matcher — import your own equipment list and immediately see which vulnerabilities are relevant, processed entirely locally in your browser, without uploading to a server.
Why IACS Radar?
Information about industrial cybersecurity is scattered across countless sources. Vulnerabilities, threat intelligence, vendor advisories, standards and practical guidelines are often offered separately. As a result it takes a lot of time to determine which information is really relevant to an industrial or OT environment.
IACS Radar aims to bring this information together and make it accessible. Not as a replacement for a professional risk analysis or technical investigation, but as a starting point for professionals who want to understand faster:
- •Which vulnerabilities may be relevant to industrial systems.
- •Which threats are developing within the energy and industrial sector.
- •How IEC 62443 can be applied in practice.
- •Which measures contribute to a resilient and manageable OT environment.
IACS Radar is thus intended for OT engineers, security professionals, asset owners, system integrators and other professionals working on reliable and demonstrably secure industrial automation.
OT security only becomes effective when policy, technology and practice speak the same language.
Purpose
Bringing together publicly observable industrial exposure, critical vulnerabilities, KEV entries, ICS advisories and IEC 62443 knowledge on one clear platform, focused on the energy sector.
Strictly defensive
IACS Radar offers no functionality for active scanning, exploitation, credential testing or unauthorised access. The platform is intended solely for risk assessment, knowledge sharing and vulnerability management.
Target audience
- • Energy companies and grid operators
- • Asset owners
- • System integrators
- • OT engineers
- • OT security specialists
- • Security officers
- • Vulnerability managers
- • Vendors
- • Auditors
- • Technical management
What this platform is not
Not an internet scanner, not an exploitation tool and not a replacement for the official IEC 62443 publications or CISA sources. See the methodology page for limitations and source accountability.
Status of this environment
This version of IACS Radar retrieves vulnerabilities and KEV entries live from CISA and NVD, ICS advisories from CISA, Siemens ProductCERT and ABB PSIRT, and uses a live Shodan integration for the exposure map. In case of an outage each source falls back independently to synthetic demonstration data — see methodology for details and per-source status.
IACS Radar is a personal and independent knowledge initiative. The content does not necessarily represent the views of my employer or clients.